Scope and who we are
Scenehand is a footage-intelligence service. You upload or connect video material; we transcribe it, split it into scenes, tag it and make it searchable, and we answer questions about it with citations back to a scene and a timecode.
This policy applies to the Scenehand web application, the Scenehand desktop application for macOS, the Slack integration, and the scenehand.studio website. It covers both the material you entrust to us and the data we hold about you as a customer.
The controller for the purposes of this policy is Scenehand, contactable as set out in clause 16. Where a signed service agreement or data processing agreement is in place, the parties and notice provisions in that agreement take precedence over this clause.
This policy sits alongside, and does not narrow, the data-protection rights you already hold where you are: where UK GDPR, the EU GDPR or another regime applies to you, we apply it, and where two of them would give you different protection, we apply the stronger.
Definitions
These are the terms the product itself uses, and they carry the same meaning here.
- Footage
- Video and audio material you upload or connect, including its embedded metadata and timecode.
- Workspace
- The private account boundary your projects and members sit inside. Nothing crosses it.
- Analysis data
- Everything derived from footage: transcripts, speaker labels, scenes, tags, embeddings and story notes.
- Proxy
- A compressed copy generated for playback and analysis. In browser upload, only the proxy is transmitted.
- Customer content
- Footage, analysis data, comments, tag libraries and anything else you or your members put into a project.
- Credit
- The billing unit: one hour of Standard analysis. Consumption is metered per workspace.
What we process
Name, work email address, your role in the workspace, authentication records and session data. Where your organisation signs in with Google, Microsoft or SSO, we receive an identifier and the profile fields that provider releases; we do not receive or store your password.
The footage you upload or connect, and everything you create around it: comments, tags, project names and member lists. Footage frequently contains personal data — faces, voices, names spoken aloud, locations. You decide what enters a project; we process it on your instructions only.
Transcripts, speaker labels, scene boundaries, shot attributes, detected objects, embeddings and story notes. This is derived from your footage, is treated as customer content throughout, and is deleted with it.
Credit consumption, processing job records, ingest and error logs, application version, operating system and IP address. We use this to run the service, meter billing accurately, and diagnose failures you report.
Plan, seat count, billing address, invoices and payment status. Card details are entered with our payment processor and are never transmitted to or stored by Scenehand.
We do not buy data about you, we do not run advertising or third-party ad trackers, and we do not build profiles of individuals appearing in your footage beyond the speaker and appearance labels that make a project searchable to its own team.
Controller and processor roles
The distinction matters, because it determines who answers to the people in your footage.
You decide what footage is captured, what consents or releases stand behind it, who may see it and how long it is kept. Scenehand acts as your processor and follows your instructions, expressed through the product and through any data processing agreement between us.
For the data described in clauses 3.1, 3.4 and 3.5 we determine the purposes ourselves — running the service, metering it, securing it and invoicing it — and the legal bases in clause 5 apply.
Purposes and legal bases
Where we act as controller, we rely on the following.
AI processing and training
Analysis is the product, so this clause is the one most customers turn to first.
- Your footage is not used to train models. Not ours, not a third party's. There is no setting that opts you in, because there is no mechanism to opt into.
- Analysis stays inside your workspace. Transcripts, tags and embeddings are scoped to the project they came from. Nothing learned from one customer's footage improves, informs or leaks into another's results.
- Answers are grounded, not generated from memory. Ask and Story answer only from evidence in your own project and cite a scene and timecode for every claim. Where the footage cannot support an answer, the product says so rather than inventing one.
- No automated decisions about people. Nothing in Scenehand produces a legal or similarly significant decision about an individual. Speaker and appearance labels exist to make a project searchable by its own team, and are editable by that team.
- AI proposes; a person approves. Where the product suggests a change — a tag, an in/out range, a jump — it is applied only when a member accepts it.
Transcription and inference run on managed model APIs. We engage a provider only where its terms forbid training on the data we send and forbid retaining it beyond the processing call — a condition of engagement, not a preference. The provider in use, and its processing location, are named in the sub-processor list issued with the data processing agreement in clause 12; they are not fixed here because a provider may be replaced on notice under clause 7.
Sub-processors
We engage a deliberately short list, and only where a function cannot sensibly be run in-house. Each is bound by written terms no less protective than this policy.
We will give notice of a new or replacement sub-processor before it begins processing customer content, and customers under a data processing agreement may object on reasonable data-protection grounds.
Hosting and international transfers
Footage and analysis data are hosted in a single cloud region. That region is stated in your service agreement and confirmed on request before you upload anything — ask first if you have a residency requirement, because customer-selectable regions are not offered yet. Enterprise customers can instead run Scenehand on their own infrastructure, or connect their own storage container, so that material never leaves an estate they control.
Where personal data is transferred outside its region of origin, that transfer relies on the European Commission's standard contractual clauses, or the UK International Data Transfer Agreement where UK law applies to you. Both form part of the data processing agreement in clause 12, and we will provide the version relied on for your workspace on request.
Security measures
These are the controls in place today. We would rather understate them than have a procurement team discover the gap themselves.
If a personal-data breach affects your content, we will notify you without undue delay, with what we know, what we are doing and what we recommend you do — and we would rather tell you early and revise than tell you late and complete.
Retention and deletion
There is no separate archive of your material, and nothing is held back for training. Cancelling a plan does not delete your library: it stops future charges and leaves the workspace readable to the end of the paid period.
Your rights
Subject to the law that applies to you, you may request access to your personal data, correction of it, erasure, a portable copy, restriction of processing, or object to processing we base on legitimate interests. Where we rely on consent, you may withdraw it at any time.
Much of this you can exercise yourself, without asking us: correct a speaker name, delete a project, export a transcript, remove a member, or delete the whole account from Settings. For anything else, write to us at the address in clause 16. We will respond within one month and will not charge you for a first request.
If you appear in footage held by one of our customers and want it corrected or removed, the customer is the controller of that material and the right route is to them. Tell us and we will pass the request on and support them in acting on it, but we cannot alter another organisation's content on our own initiative.
Data processing agreements
A data processing agreement is available for Enterprise customers, covering our processor obligations, the sub-processor list, transfer mechanisms, breach notification and audit rights. On-premise deployment and enforced SSO are available on the same plan, for organisations whose footage cannot sit with a vendor at all.
Ask for the DPA and the current sub-processor list together — they are maintained as one document. Talk to sales →
Children
Scenehand is a professional tool sold to organisations, and accounts are not offered to children. Footage may of course contain children — a documentary, a school, a hospital — and where it does, the consents and safeguards behind that material are the responsibility of the customer who captured it. We recommend you record those consents alongside the project.
Changes to this policy
We will post a revised version here with a new effective date and version number. Where a change materially affects how we handle customer content, we will tell workspace Managers by email before it takes effect, rather than relying on you to notice a date change.
Contact and complaints
privacy@scenehand.studio — include the workspace name and, if you are writing about specific material, the project and file.
Product and technical questions go to support@scenehand.studio; contracts and DPAs to sales. Replies within one working day, Monday to Friday.
If you are not satisfied with how we have handled a privacy matter, you may complain to your local supervisory authority. We would rather you came to us first, and we will tell you what we can and cannot do.
Send written correspondence to the privacy address above; a postal address is available on request.